Active Directory Design Question


i doing assignment , in have been asked design active directory head office in melbourne , 1 branch office in state. thinking of creating child domain each state, , each store part of there local state domain. each store have group policy part of there local child domain. thought head office have own group policy need part of own store , part of other states well, within child domain. ceo, need authority of head office domain , other states domains well, done trusts or inheritance?. how can state group policies part of regional management ou without being part of there local staff ous?

hello,

why use of child domains?

if want use child domains recommanded have @ least 2 dcs servers per domain.

you can use 1 domain with:

  • two rwdc in head office: 2 dc/dns/gc servers
  • one rodc enabled password caching in branch office

that enough ensure high-availability of ad service , wan connections between head , branch office down, users in branch office still able logon.

if planning add child domains multiple password policies, can use 1 domain 2008 dcs , create multiple psos.

for more information ad ds fine-grained password policies, refer microsoft article:

http://technet.microsoft.com/en-us/library/cc770394(ws.10).aspx

for group policies, can link them sites.

microsoft student partner

microsoft certified professional
microsoft certified systems administrator: security
microsoft certified systems engineer: security
microsoft certified technology specialist: windows server 2008 active directory, configuration
microsoft certified technology specialist: windows server 2008 network infrastructure, configuration


this posting provided "as is" no warranties or guarantees , , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group